500-290 Exam Questions
70 real 500-290 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which option transmits policy-based alerts such as SNMP and syslog?
- Question #2
Which option is used to implement suppression in the Rule Management user interface?
- Question #3
FireSIGHT recommendations appear in which layer of the Policy Layers page?
- Question #4
In addition to the discovery of new hosts, FireSIGHT can also perform which function?
- Question #5
A user discovery agent can be installed on which platform?
- Question #6
Other than navigating to the Network File Trajectory page for a file, which option is an alternative way of accessing the network trajectory of a file?
- Question #7
Which option can you enter in the Search text box to look for the trajectory of a particular file?
- Question #8
A context box opens when you click on an event icon in the Network File Trajectory map for a file. Which option is an element of the box?
- Question #9
Which Cisco IPS signature parameter can be tuned to reduce the volume of the alerts that are written to the event store?
- Question #10
Which two operations would put an inline Cisco IPS sensor in detection mode? (Choose two.)
- Question #11
Which two are valid examples of String engines? (Choose two.)
- Question #12
Which two are the functions of the learning feature of anomaly detection within a Cisco IPS appliance? (Choose two.)
- Question #13
Regarding the Cisco IPS appliance anomaly detection feature, which two of these would be considered scan events? (Choose two.)
- Question #14
According to Gartner, which criteria distinguish a next-generation IPS?
- Question #15
Which feature in the Cisco AMP solution provides the ability to track malware activity over time?
- Question #16
Which Cisco AMP deployment would you recommend for advanced customers that want comprehensive threat protection, investigation, and response?
- Question #17
The gateway VPN feature supports which deployment types?
- Question #18
Which statement is true concerning static NAT?
- Question #19
Which statement is true when network traffic meets the criteria specified in a correlation rule?
- Question #20
Which list identifies the possible types of alerts that the Sourcefire System can generate as notification of events or policy violations?
- Question #21
Which option is a remediation module that comes with the Sourcefire System?
- Question #22
Which statement represents detection capabilities of the HTTP preprocessor?
- Question #23
Which feature of the preprocessor configuration pages lets you quickly jump to a list of the rules associated with the preprocessor that you are configuring?
- Question #24
Suppose an administrator is configuring an IPS policy and attempts to enable intrusion rules that require the operation of the TCP stream preprocessor, but the TCP stream preproces...
- Question #25
Controlling simultaneous connections is a feature of which type of preprocessor?
- Question #26
A one-to-many type of scan, in which an attacker uses a single host to scan a single port on multiple target hosts, indicates which port scan type?
- Question #27
What does packet latency thresholding measure?
- Question #28
What are the two categories of variables that you can configure in Object Management?
- Question #29
Which option is true regarding the $HOME_NET variable?
- Question #30
Which option is one of the three methods of updating the IP addresses in Sourcefire Security Intelligence?
- Question #31
Which statement is true in regard to the Sourcefire Security Intelligence lists?
- Question #32
Which statement is true when adding a network to an access control rule?
- Question #33
Which option is true when configuring an access control rule?
- Question #34
How do you configure URL filtering?
- Question #35
Which statement describes the meaning of a red health status icon?
- Question #36
Context Explorer can be accessed by a subset of user roles. Which predefined user role is not valid for FireSIGHT event access?
- Question #37
Context Explorer can be accessed by a subset of user roles. Which predefined user role is valid for FireSIGHT event access?
- Question #38
When configuring an LDAP authentication object, which server type is available?
- Question #39
Cisco FireSIGHT can provide visibility into which three types of information that competing products cannot? (Choose three.)
- Question #40
When adding source and destination ports in the Ports tab of the access control policy rule editor, which restriction is in place?
- Question #41
Access control policy rules can be configured to block based on the conditions that you specify in each rule. Which behavior block response do you use if you want to deny and reset...
- Question #42
Which event source can have a default workflow configured?
- Question #43
Where do you configure widget properties?
- Question #44
The collection of health modules and their settings is known as which option?
- Question #45
Host criticality is an example of which option?
- Question #46
FireSIGHT uses three primary types of detection to understand the environment in which it is deployed. Which option is one of the detection types?
- Question #47
When configuring FireSIGHT detection, an administrator would create a network discovery policy and set the action to "discover". Which option is a possible type of discovery?
- Question #48
Which option is derived from the discovery component of FireSIGHT technology?
- Question #49
The IP address::/0 is equivalent to which IPv4 address and netmask?
- Question #50
One of the goals of geolocation is to identify which option?